{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "sourcegraph-mcp",
    "name": "Sourcegraph MCP Server",
    "vendor": "Sourcegraph, Inc.",
    "vendorUrl": "https://sourcegraph.com",
    "kind": "mcp",
    "category": "code",
    "summary": "Sourcegraph's official MCP server gives AI agents code search, file reading, code navigation and commit and diff search across the repositories indexed by a company's Sourcegraph instance. It is built into Enterprise instances at /.api/mcp.",
    "url": "https://www.anchorterminal.com/tools/sourcegraph-mcp",
    "markdownUrl": "https://www.anchorterminal.com/tools/sourcegraph-mcp.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sourcegraph-mcp.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sourcegraph-mcp.json",
    "license": "Proprietary. The server is part of the Sourcegraph Enterprise product under the Sourcegraph Terms of Service",
    "transports": [
      "streamable-http"
    ],
    "packages": [],
    "auth": "mixed",
    "authNotes": "An admin of a Sourcegraph Enterprise instance must exist first, and access starts with a sales contract or an approved trial. On the instance, MCP clients use OAuth 2.0 with PKCE and register themselves through dynamic client registration, which is on by default and limited to the `mcp` scope. A user approves the grant in a browser. Admins can disable registration and pre-register public clients. Clients without OAuth send a Sourcegraph access token as `Authorization: token \u003ctoken\u003e`, and the token can carry the `mcp` scope. Users need the `MCP#ACCESS` permission, granted to the User role by default.",
    "pricing": "paid",
    "pricingNotes": "Enterprise plans only. The pricing page lists one plan, starting at a $16K minimum annual contract that scales with team size, bought through sales. No per-user or per-call price is published. The plan includes credits for AI tools, and `code_finder` and Deep Search draw on that entitlement. A Sourcegraph Cloud trial is available on request and subject to eligibility, with no sandbox or free tier found (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the MCP docs, the authentication docs or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 16,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://sourcegraph.com/docs/api/mcp",
    "registryName": "io.github.sourcegraph/mcp",
    "capabilities": [
      "code.repo",
      "code.git"
    ],
    "tags": [
      "official",
      "mcp",
      "hosted",
      "self-hosted",
      "enterprise",
      "oauth",
      "read-only",
      "code-search",
      "sales-led",
      "soc2"
    ],
    "lastRelease": "2026-09-17",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 57.5,
      "grade": "C",
      "agentReady": false,
      "rank": 420,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 72,
        "maintenance": 83,
        "payments": 15,
        "reliability": 25,
        "schema": 71,
        "security": 76,
        "transparency": 78
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 25,
          "points": 5,
          "reason": "Scored with the hosted lines, because the server is an HTTP endpoint on a Sourcegraph Cloud or self-hosted instance. The site links a status page at sourcegraphstatus.com, but the host did not resolve from our network on 8 October 2026, so the page and its history are unread and scored as absent (0 + 0). This is our fetch failure, not an established gap. No request rate limits for the MCP endpoints were found in the reviewed documentation, only result limits per tool (0). No 429 or backoff guidance was found. Release 8.0.0 says search tools now separate incomplete searches from empty results and recommend a retry, and every tool reads, so retries are safe (5). The SLA page commits to 99.5 per cent monthly uptime for Sourcegraph Cloud on Enterprise plans (10). The server carries no beta label, and Code Finder became generally available on 20 August 2026 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 71,
          "points": 11.54,
          "reason": "The docs list each tool's parameters with required and optional marks, defaults and maximums. We could not read the tool definitions themselves, because every endpoint needs an Enterprise instance and sourcegraph.com answered 401, so the machine-readable contract earns partial credit (15). /llms.txt and /docs/llms.txt return 404, but every docs page is served as Markdown at its URL plus .md (10). Tool entries state use cases, `code_finder` has best practices and a contrast with `deepsearch`, and a matrix shows which endpoint carries which tool (14). Required fields, defaults and bounds are documented, while search filters travel inside one query string and `evaluator` takes a free Lua script (9). `list_refs` has JSON examples and the authentication page has a troubleshooting table for `invalid_scope`, 401, 403 and 404, with no catalogue of tool errors (8). Versioned releases with dated MCP entries in the changelog (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 72,
          "points": 11.7,
          "reason": "Sixteen documented tools on /.api/mcp/all, nine on the default endpoint and two on /.api/mcp/deepsearch, and admins can remove tools with `mcp.tools.disabled`. Definition sizes are unread (23). Result limits on every list and search tool, an `after` cursor on `compare_revisions`, `count` on searches and line ranges on `read_file` (17). Search tools report incomplete results with retry advice per the 8.0.0 notes, and HTTP 401, 403 and 404 causes are documented, but no tool error list was found (10). No tool writes to a repository, so repeating a call is safe. `deepsearch` creates a conversation each time, and we could not read the readOnlyHint or destructiveHint annotations (10). Most tools need one to three parameters with stated defaults. There is no SDK to count, as the surface is MCP only (12)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 76,
          "points": 13.3,
          "reason": "OAuth 2.0 with PKCE, dynamic client registration held to the `mcp` scope, one-hour access tokens, a revocation endpoint and bearer tokens in the header only. Access tokens can also carry the `mcp` scope and default to a 90-day expiry (30). Every documented tool reads, repository permissions apply to each call, and admins can gate MCP by RBAC role or disable single tools. There is no per-repository grant narrower than the user's own access (18). The tools return repository content, which is untrusted input. The consent screen warns that the `mcp` scope grants read access to private code, and no prompt-injection guidance was found (4). The audit log records access token use, repository access and API requests as structured logs for a SIEM. No MCP-specific call log is documented (9). SOC 2 and ISO/IEC 27001:2022 on the security portal, annual third-party penetration tests, CVE fixes named in release notes and an invite-only HackerOne programme reached through security@sourcegraph.com. security.txt returns 404 (15)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 15,
          "points": 1.88,
          "reason": "No x402, MPP or L402 (0). The pricing page publishes a starting figure, a $16K minimum annual contract, with no per-user or per-call price and a contact-sales button, so half of the plan-pricing credit (5). A free Sourcegraph Cloud trial exists by request, with eligibility reviewed and a wait of up to an hour in business hours. No card is mentioned, so half credit (10). An agent cannot gain access alone. A company needs a contract or an approved trial, and a user approves OAuth in a browser (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 83,
          "points": 7.26,
          "reason": "The latest Cloud update notes are dated 5 October 2026, and self-hosted 8.0.0 shipped on 17 September 2026 with a new `list_refs` tool (30). Four self-hosted releases since 10 July 2026 (7.6.0, 7.7.0, 7.7.359, 8.0.0) plus weekly update notes (20). A closed service with a public changelog, support at support@sourcegraph.com and published response times from two business hours for Enterprise. No public issue tracker for the server was found (12). Listed in the official MCP registry as io.github.sourcegraph/mcp (15). Release 7.6.0 moved to the MCP Go SDK v1.7.0 and protocol version 2026-07-28, and releases name the CVEs they fix. No public CI to read (6)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 78,
          "points": 6.83,
          "note": "editorial 65, provenance 90",
          "reason": "Closed source under the Sourcegraph Terms of Service, last modified 22 July 2026, with supplemental terms listed in one index (15). The terms, the DPA, the security page and the privacy policy describe data handling. Cloud logs are kept up to 365 days, partner LLMs keep inputs only for abuse detection, and the privacy policy excludes customer code, which falls under the customer agreement. No retention period for code or search queries on Cloud was found (22). The current and previous major versions are supported, and release notes date removals such as the end of GitHub Enterprise Server 3.3 support, but no deprecation policy with a notice period for MCP tools was found (10). Sub-processors are listed with locations and purposes, last modified 21 August 2026, with email notice of changes, and instance telemetry is documented (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Sixteen documented tools on /.api/mcp/all, nine on the default endpoint and two on /.api/mcp/deepsearch, and admins can remove tools with `mcp.tools.disabled`. Definition sizes are unread (23). Result limits on every list and search tool, an `after` cursor on `compare_revisions`, `count` on searches and line ranges on `read_file` (17). Search tools report incomplete results with retry advice per the 8.0.0 notes, and HTTP 401, 403 and 404 causes are documented, but no tool error list was found (10). No tool writes to a repository, so repeating a call is safe. `deepsearch` creates a conversation each time, and we could not read the readOnlyHint or destructiveHint annotations (10). Most tools need one to three parameters with stated defaults. There is no SDK to count, as the surface is MCP only (12).",
          "maintenance": "The latest Cloud update notes are dated 5 October 2026, and self-hosted 8.0.0 shipped on 17 September 2026 with a new `list_refs` tool (30). Four self-hosted releases since 10 July 2026 (7.6.0, 7.7.0, 7.7.359, 8.0.0) plus weekly update notes (20). A closed service with a public changelog, support at support@sourcegraph.com and published response times from two business hours for Enterprise. No public issue tracker for the server was found (12). Listed in the official MCP registry as io.github.sourcegraph/mcp (15). Release 7.6.0 moved to the MCP Go SDK v1.7.0 and protocol version 2026-07-28, and releases name the CVEs they fix. No public CI to read (6).",
          "payments": "No x402, MPP or L402 (0). The pricing page publishes a starting figure, a $16K minimum annual contract, with no per-user or per-call price and a contact-sales button, so half of the plan-pricing credit (5). A free Sourcegraph Cloud trial exists by request, with eligibility reviewed and a wait of up to an hour in business hours. No card is mentioned, so half credit (10). An agent cannot gain access alone. A company needs a contract or an approved trial, and a user approves OAuth in a browser (0).",
          "reliability": "Scored with the hosted lines, because the server is an HTTP endpoint on a Sourcegraph Cloud or self-hosted instance. The site links a status page at sourcegraphstatus.com, but the host did not resolve from our network on 8 October 2026, so the page and its history are unread and scored as absent (0 + 0). This is our fetch failure, not an established gap. No request rate limits for the MCP endpoints were found in the reviewed documentation, only result limits per tool (0). No 429 or backoff guidance was found. Release 8.0.0 says search tools now separate incomplete searches from empty results and recommend a retry, and every tool reads, so retries are safe (5). The SLA page commits to 99.5 per cent monthly uptime for Sourcegraph Cloud on Enterprise plans (10). The server carries no beta label, and Code Finder became generally available on 20 August 2026 (10).",
          "schema": "The docs list each tool's parameters with required and optional marks, defaults and maximums. We could not read the tool definitions themselves, because every endpoint needs an Enterprise instance and sourcegraph.com answered 401, so the machine-readable contract earns partial credit (15). /llms.txt and /docs/llms.txt return 404, but every docs page is served as Markdown at its URL plus .md (10). Tool entries state use cases, `code_finder` has best practices and a contrast with `deepsearch`, and a matrix shows which endpoint carries which tool (14). Required fields, defaults and bounds are documented, while search filters travel inside one query string and `evaluator` takes a free Lua script (9). `list_refs` has JSON examples and the authentication page has a troubleshooting table for `invalid_scope`, 401, 403 and 404, with no catalogue of tool errors (8). Versioned releases with dated MCP entries in the changelog (15).",
          "security": "OAuth 2.0 with PKCE, dynamic client registration held to the `mcp` scope, one-hour access tokens, a revocation endpoint and bearer tokens in the header only. Access tokens can also carry the `mcp` scope and default to a 90-day expiry (30). Every documented tool reads, repository permissions apply to each call, and admins can gate MCP by RBAC role or disable single tools. There is no per-repository grant narrower than the user's own access (18). The tools return repository content, which is untrusted input. The consent screen warns that the `mcp` scope grants read access to private code, and no prompt-injection guidance was found (4). The audit log records access token use, repository access and API requests as structured logs for a SIEM. No MCP-specific call log is documented (9). SOC 2 and ISO/IEC 27001:2022 on the security portal, annual third-party penetration tests, CVE fixes named in release notes and an invite-only HackerOne programme reached through security@sourcegraph.com. security.txt returns 404 (15).",
          "transparency": "Closed source under the Sourcegraph Terms of Service, last modified 22 July 2026, with supplemental terms listed in one index (15). The terms, the DPA, the security page and the privacy policy describe data handling. Cloud logs are kept up to 365 days, partner LLMs keep inputs only for abuse detection, and the privacy policy excludes customer code, which falls under the customer agreement. No retention period for code or search queries on Cloud was found (22). The current and previous major versions are supported, and release notes date removals such as the end of GitHub Enterprise Server 3.3 support, but no deprecation policy with a notice period for MCP tools was found (10). Sub-processors are listed with locations and purposes, last modified 21 August 2026, with email notice of changes, and instance telemetry is documented (18)."
        },
        "sources": [
          {
            "what": "MCP server docs, tools and endpoint matrix",
            "url": "https://sourcegraph.com/docs/api/mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP authentication",
            "url": "https://sourcegraph.com/docs/api/mcp/authentication.md",
            "seen": "2026-10-08"
          },
          {
            "what": "client setup",
            "url": "https://sourcegraph.com/docs/api/mcp/client-integrations.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth apps, scopes and token lifetimes",
            "url": "https://sourcegraph.com/docs/admin/oauth-apps.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth protected-resource metadata, and the 401 from the endpoint",
            "url": "https://sourcegraph.com/.well-known/oauth-protected-resource/.api/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://sourcegraph.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud trial and regions",
            "url": "https://sourcegraph.com/docs/cloud.md",
            "seen": "2026-10-08"
          },
          {
            "what": "SLA and support response times",
            "url": "https://sourcegraph.com/docs/sla.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://sourcegraph.com/changelog/releases",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://sourcegraph.com/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "site configuration defaults (mcp.enabled, access token expiry)",
            "url": "https://sourcegraph.com/docs/admin/config/site-config.md",
            "seen": "2026-10-08"
          },
          {
            "what": "audit log",
            "url": "https://sourcegraph.com/docs/admin/audit-log.md",
            "seen": "2026-10-08"
          },
          {
            "what": "telemetry and pings",
            "url": "https://sourcegraph.com/docs/admin/telemetry.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://sourcegraph.com/security",
            "seen": "2026-10-08"
          },
          {
            "what": "security portal",
            "url": "https://security.sourcegraph.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of Service",
            "url": "https://sourcegraph.com/terms/tos",
            "seen": "2026-10-08"
          },
          {
            "what": "Privacy Policy",
            "url": "https://sourcegraph.com/terms/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://sourcegraph.com/terms/subprocessors",
            "seen": "2026-10-08"
          },
          {
            "what": "DPA",
            "url": "https://sourcegraph.com/terms/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry entry",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=sourcegraph",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP record",
            "url": "https://rdap.verisign.com/com/v1/domain/sourcegraph.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: sourcegraphstatus.com did not resolve from our network (WebFetch and curl both failed), so the status page and its incident history are unread and scored as absent.",
          "unchecked: the MCP tool definitions (JSON Schema inputs, description text, readOnlyHint and destructiveHint annotations, total size). Every endpoint needs an Enterprise instance, and sourcegraph.com/.api/mcp answered 401.",
          "unchecked: the answers in the pricing page FAQ, among them the one on a free trial, are loaded on click and were not in the page we read. The trial facts come from the Cloud docs.",
          "unchecked: the credit rate card for `code_finder` and Deep Search, which the changelog places in the Enterprise Portal.",
          "The registry entry io.github.sourcegraph/mcp points at a repository under github.com/sourcegraph-community, which we did not open.",
          "No request rate limit for the MCP endpoints was found. The security page says Cloudflare rate limiting protects Cloud domains, without numbers.",
          "The lead was right on the endpoint, the authentication methods and the Enterprise-only restriction."
        ]
      },
      "negative": 0,
      "verdict": "Sixteen read-only tools search and navigate code across every repository an instance indexes, with OAuth limited to an `mcp` scope and repository permissions enforced on each call. Access needs an Enterprise contract, priced from $16,000 a year, and no request rate limits were found in the reviewed documentation.",
      "bestFor": "A company that already runs Sourcegraph and wants agents to search and navigate many repositories with compiler-accurate definitions and references.",
      "strengths": [
        "All 16 documented tools read and none writes to a repository, with three endpoints so a client can load 9, 16 or 2 tools",
        "OAuth 2.0 with PKCE and dynamic client registration, registered clients held to the `mcp` scope, and access tokens that can carry the same scope",
        "Repository permissions apply to every call, and admins can gate MCP by role (`MCP#ACCESS`) or switch off single tools with `mcp.tools.disabled`",
        "Result limits and defaults are documented per tool, such as 1,000 directory entries, 100 commits and 200 lines for files over 128KB",
        "Listed in the official MCP registry as io.github.sourcegraph/mcp, with MCP changes in dated release notes through 2026"
      ],
      "weaknesses": [
        "Enterprise plans only, from a $16,000 minimum annual contract through sales. A Cloud trial is by request and subject to eligibility",
        "No request rate limits, 429 behaviour or tool error catalogue found in the reviewed documentation",
        "`code_finder` and Deep Search draw on the instance's credit entitlement and return an error once the quota is used up",
        "No guidance on prompt injection from repository content was found, although every search and file tool returns such content",
        "sourcegraph.com/.well-known/security.txt returns 404, and the bug bounty on HackerOne is invite-only"
      ],
      "agentNotes": [
        "Connect to https://\u003cinstance\u003e/.api/mcp for the nine core tools. Use /.api/mcp/all for `go_to_definition`, `find_references`, `nls_search` and `compare_revisions`",
        "Request only the `mcp` scope in OAuth. Any other scope on the MCP resource fails with `invalid_scope`",
        "Without OAuth, send `Authorization: token \u003caccess token\u003e` and create the token with the `mcp` scope and an expiry",
        "Call `list_repos` first and name the repository in every `code_finder` task. It declines broad searches across repositories",
        "Read large files with `startLine` and `endLine`. Files over 128KB return only the first 200 lines"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 57.5
        }
      ],
      "editorialScores": {
        "ergonomics": 72,
        "maintenance": 83,
        "payments": 15,
        "reliability": 25,
        "schema": 71,
        "security": 76,
        "transparency": 65
      },
      "provenanceScore": 90
    },
    "connect": {
      "claudeCode": "claude mcp add --transport http sourcegraph https://sourcegraph.example.com/.api/mcp",
      "config": {
        "mcpServers": {
          "sourcegraph": {
            "type": "http",
            "url": "https://sourcegraph.example.com/.api/mcp"
          }
        }
      },
      "headless": {
        "mcpServers": {
          "sourcegraph": {
            "headers": {
              "Authorization": "token ${SOURCEGRAPH_ACCESS_TOKEN}"
            },
            "type": "http",
            "url": "https://sourcegraph.example.com/.api/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/code.repo",
      "tool": "https://letme.dev/sourcegraph-mcp"
    },
    "notable": [
      "Three endpoints on each instance. /.api/mcp carries nine core tools, /.api/mcp/all carries all 16 and /.api/mcp/deepsearch carries the two Deep Search tools (https://sourcegraph.com/docs/api/mcp)",
      "The docs mark the MCP server as supported on Enterprise plans, and the pricing page lists the Enterprise plan as starting at a $16K minimum annual contract (https://sourcegraph.com/pricing)",
      "Clients registered through dynamic client registration are restricted to the `mcp` scope, and admins can turn registration off and pre-register clients (https://sourcegraph.com/docs/api/mcp/authentication)",
      "An unauthenticated request to https://sourcegraph.com/.api/mcp answered 401 with a `WWW-Authenticate` header naming the protected-resource metadata and `scope=\"mcp\"` (checked 2026-10-08)",
      "Code Finder, an agentic search tool exposed as `code_finder`, went to beta on 20 July 2026 and general availability on 20 August 2026, and is metered against the instance's entitlement (https://sourcegraph.com/changelog)",
      "The 7.6.0 release of 6 August 2026 moved the server to MCP protocol version 2026-07-28 and added the `mcp.tools.disabled` setting (https://sourcegraph.com/changelog/releases)",
      "Listed in the official MCP registry as io.github.sourcegraph/mcp, version 0.1.0, published 26 March 2026 (https://registry.modelcontextprotocol.io/v0/servers?search=sourcegraph)"
    ],
    "area": "developer",
    "details": [
      {
        "label": "Endpoints",
        "value": "https://\u003cinstance\u003e/.api/mcp (core), /.api/mcp/all (full suite), /.api/mcp/deepsearch (Deep Search only). Streamable HTTP. `mcp.enabled` defaults to true, and when false the paths return 404"
      },
      {
        "label": "Tools",
        "value": "read_file, list_files, list_repos, list_refs, keyword_search, nls_search, evaluator, go_to_definition, find_references, commit_search, diff_search, compare_revisions, get_contributor_repos, code_finder, deepsearch, deepsearch_read"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 authorisation code with PKCE (S256), dynamic client registration (RFC 7591), device flow and a revocation endpoint. Access tokens last 3,600 seconds per the OAuth docs. Sourcegraph access tokens in `Authorization: token ...` can carry the `mcp` scope, with a default expiry of 90 days"
      },
      {
        "label": "Access control",
        "value": "Repository permissions apply to every read. The `MCP#ACCESS` RBAC permission is granted to the built-in User role by default. `mcp.tools.disabled` removes named tools from all endpoints"
      },
      {
        "label": "Result limits",
        "value": "list_files 1,000 entries. list_repos default 50, maximum 10,000. list_refs default 100, maximum 500. commit_search default 50, maximum 100. diff_search default 20, maximum 50. compare_revisions default 50 file diffs, maximum 100, with an `after` cursor. find_references default 10"
      },
      {
        "label": "Metered tools",
        "value": "`code_finder` is metered against the instance's entitlement and returns an error when the quota is exhausted. The pricing page says the plan includes credits for AI tools"
      },
      {
        "label": "Plan",
        "value": "Enterprise only. Starting at a $16K minimum annual contract with single-tenant Cloud or self-hosted deployment, sold through sales (https://sourcegraph.com/pricing)"
      },
      {
        "label": "SLA",
        "value": "99.5 per cent monthly uptime commitment for Sourcegraph Cloud on Enterprise plans, measured per customer instance, with at most 10 hours of scheduled downtime a quarter (https://sourcegraph.com/docs/sla)"
      },
      {
        "label": "Releases",
        "value": "Self-hosted 8.0.0 on 17 September 2026, 7.7.359 on 27 August, 7.7.0 on 26 August and 7.6.0 on 6 August, each with MCP entries. Weekly Cloud update notes, the latest dated 5 October 2026"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 and ISO/IEC 27001:2022 listed on security.sourcegraph.com, with reports behind an access request. Annual third-party penetration tests per sourcegraph.com/security"
      },
      {
        "label": "Sub-processors",
        "value": "List last modified 21 August 2026, all located in the USA. Hosting on Google Cloud. Anthropic, Fireworks AI, Google and OpenAI process queries and code snippets sent to the AI tools (https://sourcegraph.com/terms/subprocessors)"
      },
      {
        "label": "Clients documented",
        "value": "Claude Code, Codex, Cursor, Copilot, OpenCode, Amp, Gemini Code Assist, VS Code, Antigravity and Windsurf (https://sourcegraph.com/docs/api/mcp/client-integrations)"
      }
    ],
    "provenance": {
      "legalEntity": "Sourcegraph, Inc.",
      "domain": "sourcegraph.com",
      "domainRegistered": "2012-11-25",
      "endpointOnVendorDomain": true,
      "terms": "https://sourcegraph.com/terms/tos",
      "privacy": "https://sourcegraph.com/terms/privacy",
      "statusPage": "https://sourcegraphstatus.com",
      "changelog": "https://sourcegraph.com/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Service (last modified 22 July 2026) name Sourcegraph, Inc., 548 Market St PMB 20739, San Francisco, CA 94104-5401, and govern all Sourcegraph products. Enterprise licences are bought with an order form under these terms.",
        "The Privacy Policy (last modified 12 June 2026) says it does not cover user content such as customer code, which Sourcegraph processes as a data processor under the customer agreement and the DPA at sourcegraph.com/terms/dpa.",
        "The endpoint is on the customer's own instance. Sourcegraph Cloud instances are single-tenant, and the terms describe trial instances at \u003corganisation\u003e.sourcegraph.com. A self-hosted instance answers on the customer's domain.",
        "sourcegraph.com/.well-known/security.txt and /security.txt both returned 404 on 2026-10-08. The security portal sends reports to security@sourcegraph.com.",
        "The site footer links System status to https://sourcegraphstatus.com. The host did not resolve from our network on 2026-10-08, so the page is unread.",
        "RDAP for sourcegraph.com gives a registration date of 2012-11-25."
      ],
      "score": 90,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Sourcegraph, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "sourcegraph.com, registered 2012-11-25 (13 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "sourcegraph.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "sourcegraphstatus.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://sourcegraph.com/terms/tos",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-07-22",
          "words": 7007,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last modified: July 22, 2026",
              "says": "Last updated 2026-07-22"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "You agree to submit to the personal jurisdiction of the federal and state courts located in San Francisco, California, USA (\"Forum\") for any actions for which we retain the right to seek injunctive or other equitable relief in a court of competent jurisdiction to prevent the actual or threatened infringement, misappro…",
              "says": "Disputes go to the courts of San Francisco, California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Short version: Each party's liability is limited to direct damages wherever possible, and to the amount you paid us for access to the services."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "termination When and how your account can be terminated"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We may provide you with (and you hereby consent to our provision of) notices, including those regarding changes to our terms and conditions, by email, regular mail, or postings on the Services.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You may not, and may not permit any third-party to copy, modify, decompile, reverse engineer, redistribute, encumber, sell, rent, lease, sublicense, or otherwise transfer rights to all or any part of the Services or Code Data without our prior written approval."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "(iii) Our Service Level Agreements (SLAs) and support commitments only apply to Supported Versions."
            }
          ],
          "toKnow": [
            {
              "key": "training.optout",
              "label": "Says it may use customer content to train or improve models, and gives an opt-out",
              "found": true,
              "quote": "You further agree that, unless you opt out, AI User Content may be used to improve and support"
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "If we discover that an Account is being used by a user under thirteen (13) years old, we will terminate that Account immediately without notice to you."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "THE AGREEMENT CONTAINS A MANDATORY INDIVIDUAL ARBITRATION AND CLASS ACTION/JURY TRIAL WAIVER PROVISION THAT REQUIRES THE USE OF ARBITRATION ON AN INDIVIDUAL BASIS TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS ACTIONS."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Subscriptions signed on an Order Form renew for one year terms at the then-current fees unless 45 days' written notice of non-renewal is given.",
              "quote": "shall renew for one (1) year terms at the then-current fees and your payment method will be charged"
            },
            {
              "date": "2026-10-08",
              "text": "Sourcegraph may use an organisation's name and logo to identify it as a customer unless an Order Form says otherwise.",
              "quote": "Organization, we may use your name and logo to identify you as a customer and use product testimonials"
            },
            {
              "date": "2026-10-08",
              "text": "Customers agree not to store sensitive data in the services, a category the terms define to include passwords, private encryption keys and other credentials.",
              "quote": "designed to store Sensitive Data (as defined below), and (ii) you will not use the Services to store"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://sourcegraph.com/terms/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-12",
          "words": 4251,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last modified: June 12, 2026",
              "says": "Last updated 2026-06-12"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "How We Use Cookies and Similar Technologies Personal Data We Receive from Third Parties Personal Data We Derive from Your Use of the Services Personal Data We Collect As Defined Under CCPA Personal Data We Do Not Collect"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain each category of personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, including to satisfy legal, tax, audit, and accounting obligations, resolve disputes, and enforce our agreements.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "When you authenticate through third-party services (such as single sign-on providers), those providers' privacy policies govern what information is shared with us."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell or share personal data for cross-context behavioral advertising as defined under applicable privacy laws.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to access and receive a copy of the personal data we hold about you in a structured, commonly used, machine-readable format."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If we deny your request, you have the right to appeal that decision by contacting us at privacy@sourcegraph.com.",
              "says": "privacy@sourcegraph.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "For personal data originating from the EEA, UK, or Switzerland, we rely on the Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner's Office as the legal mechanism for transferring your personal data to the United States.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "When an integration is enabled, including an AI coding agent connected through Sourcegraph's MCP, personal data may be shared with that third party under its own privacy practices.",
              "quote": "organization enable an integration, personal data may be shared with that third party under their"
            },
            {
              "date": "2026-10-08",
              "text": "Usage data that has been aggregated or de-identified may be used or disclosed by Sourcegraph for any purpose.",
              "quote": "longer personal data under applicable privacy laws, and we may use or disclose it for any purpose,"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/sourcegraph-mcp.json",
    "live": {
      "slug": "sourcegraph-mcp",
      "vendorStatus": {
        "page": "https://sourcegraphstatus.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:06:59.603772906Z"
      },
      "pages": [
        {
          "url": "https://sourcegraph.com/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:30.344413737Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "743412956873"
        },
        {
          "url": "https://sourcegraph.com/terms/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:32.58524964Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "6bdc63b69298"
        },
        {
          "url": "https://sourcegraph.com/terms/tos",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:24:34.583486638Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "055b6e504d93"
        }
      ],
      "updatedAt": "2026-10-08T19:06:59.603772906Z"
    }
  }
}
